Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Proofpoint PPAN01 Exam - Topic 2 Question 12 Discussion

An analyst is reviewing the Notable Senders section in Proofpoint Supplier Threat Protection.Based on the data shown in the exhibit, which vendor's email activity should be investigated first?
C) bob@aerowestglobalservices.com
A) charlie@bluehorizonpartners.io
B) alice@clariontechsolutions.net
D) jane@cypressnetworksinc.com

Proofpoint PPAN01 Exam - Topic 2 Question 12 Discussion

Actual exam question for Proofpoint's PPAN01 exam
Question #: 12
Topic #: 2
[All PPAN01 Questions]

An analyst is reviewing the Notable Senders section in Proofpoint Supplier Threat Protection.

Based on the data shown in the exhibit, which vendor's email activity should be investigated first?

Show Suggested Answer Hide Answer
Suggested Answer: C

Supplier Threat Protection prioritization focuses on vendor identities whose messaging patterns indicate elevated risk---such as unusual sending behavior, higher malicious/suspicious message counts, abnormal spike patterns, or stronger impersonation/compromise indicators relative to other suppliers. Based on the exhibit's Notable Senders metrics, bob@aerowestglobalservices.com (C) shows the highest-risk activity and should be investigated first. In Proofpoint IR workflow, supplier-related threats are high impact because they exploit trust relationships and can bypass user suspicion (invoice/payment workflows, shared documents, ongoing threads). The investigation typically validates whether this is: (1) a compromised supplier mailbox, (2) supplier-domain impersonation (lookalike domain), or (3) a legitimate supplier system misconfigured and sending risky content. Analysts pivot into message samples, authentication alignment (SPF/DKIM/DMARC), sending infrastructure changes, and recipient targeting patterns (finance/AP, executives). If malicious, containment includes blocking the supplier sender/domain (or precise subdomains), pulling delivered copies via TRAP, alerting impacted users, and initiating vendor contact to remediate the supplier's account security.


Contribute your Thoughts:

0/2000 characters
Tasia
2 hours ago
I’m leaning towards bob@aerowestglobalservices.com because I think he had a spike in emails last time we checked, but I could be wrong.
upvoted 0 times
...
Alyce
5 days ago
I feel like charlie@bluehorizonpartners.io had some red flags in our last review session, but I can't recall the specifics.
upvoted 0 times
...
Desirae
10 days ago
I remember a practice question where we had to look for the highest volume of emails sent. Maybe that's the key here too?
upvoted 0 times
...
Quentin
16 days ago
I think we discussed how to prioritize vendors based on unusual activity, but I'm not sure which one stands out here.
upvoted 0 times
...

Save Cancel